Skip to main content

💼 9.2 Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service

  • Contextual name: 💼 9.2 Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service
  • ID: /frameworks/cis-azure-v1.1.0/09/02
  • Located in: 💼 9 AppService

Description

Azure Web Apps allows sites to run under both HTTP and HTTPS by default. Web apps can be accessed by anyone using non-secure HTTP links by default. Non-secure HTTP requests can be restricted and all HTTP requests redirected to the secure HTTPS port. It is recommended to enforce HTTPS-only traffic.

Similar

  • Internal
    • ID: dec-c-8c0c667b

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 Azure App Service HTTPS Only configuration is not enabled 🟢1🟢 x6

Internal Rules

RulePoliciesFlags
✉️ dec-x-75db76ad1